« MDL: URL Clearing House in testing phase
Crontab way around in Linux »

Fake porn, fake watches and hacking your wallet

November 3rd, 2009

Fake porn sites (real Trojan Horses), fake watches (real scams), password cracking (wallet cracking) : Welcome to the world of online crime!

All these sites were taken from the same IP address, namely 210.51.187.{sanitized}. I’m going to show you a wide portfolio of online threats and scams.

To start off, a fake porn site called Pornotube pushes some mailicious files onto your computer. There is the nice way (an EXE file) or the hard way (a malicious PDF).

1

2

The files are detected by most AV products:

http://www.virustotal.com/analisis/2b6cc5d84db7dd946ee8358ec2bf40435755ef9895e10c4fe13b513f8f8a255e-1257269784

http://www.virustotal.com/analisis/4d0fe75335c352ef7bb544e6b1eea9d1dd2d083a260292275be75580ce98efca-1257224665

Oh, and there’s the cousin website as well, with another PDF exploit ‘in-your-face’.  Those sites are nasty looking, but that’s another story.

3

Now, on to the fake watches. What better way than putting a bit of a Swiss flag in there too… Yes, the Swiss are known for their quaility products, and watches in particular. The first time I flew to Geneva, I was amazed by just how many ads and posters of watches were all throughout the airport. If you take a walk near lake Geneva (le Leman), you will see many old buildings with big signs on them, such as Omega, TAG Heuer etc. I stopped in front of a Cartier store to look at some of the watches, of course none of them had price tags on ;-)
You may get the feeling that I like watches hehe… I have a nice (although modest) Swiss Military watch.

Back to our story, here is a “replica” site… I personally would call it a “counterfeit” store, but it wouldn’t sound as nice, would it? They offer “Free shipping worldwide”, how convenient! I really hate counterfeit stuff. Recently I read an article about that industry in China and it really is an out of control problem.

4

Finally, a page designed for those who want to hack the Russian version of Facebook (vkontakte.ru):

5

I had Google translate the Russian text for me:

6

Payment can be made through one of these institutions:

8

Anything else for you today?

Please note that ICQ hacks are on the ‘winter sale’:

icq2

icq

Don’t forget to use the:

icq3

;-)

Jerome Segura

Warning: all links contained in this post may be dangerous!

    This entry was posted on Tuesday, November 3rd, 2009 at 10:50 am and is filed under Malware Trends. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

    Comments:

    • (0) comments
    • |
    • Add your comments




RSS feed to this site Twitter Linkedin YouTube Channel

 

RSS feed to this site Jerome Segura is a Security Analyst working at ParetoLogic.

You can contact him at:
MalwareDiaries Email

 

Pages

  • Live Malware Map
  • VB2009 pictures
  • Zheng™ Technology
  • About
  • Contact Us



Security Software

  • XoftSpySE Anti-Spyware
  • Anti-Virus PLUS
  • Privacy Controls



Malware Top 10

  • Koobface Worm
  • DNS Changer Trojan
  • Fake Alert Trojan
  • Windows System Suite
  • Smart Protector
  • Home Antivirus 2010
  • PC Antispyware 2010
  • System Security
  • AVCare
  • Perfect Defender 2009



Archives

  • November 2009
  • October 2009
  • September 2009
  • August 2009
  • July 2009
  • June 2009
  • May 2009
  • April 2009
  • March 2009
  • February 2009
  • January 2009
  • December 2008
  • November 2008
  • October 2008
  • September 2008
  • August 2008
  • July 2008
  • June 2008
  • May 2008
  • April 2008
  • March 2008



Categories

  • Adware (1)
  • Banker Trojans (3)
  • Botnets (2)
  • Conferences (4)
  • DDos (1)
  • Exploits (33)
  • Fake codecs (30)
  • IM threats (1)
  • Interviews (5)
  • Keyloggers (1)
  • Mac security (15)
  • Malware Trends (67)
  • Phishing (7)
  • Podcast (1)
  • ransomware (1)
  • Research (33)
  • Rogue software (47)
  • Rootkits (2)
  • scams (3)
  • Social Networking (4)
  • Uncategorized (110)
  • Wireless Security (1)
  • world map (1)



 
 
 

© 2009 ParetoLogic Inc.